SQL injection in SuiteCRM - CVE-2026-69145
Published: August 6, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to SQL injection in the AOR Reports report SQL construction logic when viewing a report containing a crafted aor_fields.field value. A remote user can create or edit a report to store a malicious field value and trigger SQL execution to disclose sensitive information.
Exploitation requires permission to create or edit AOR Reports.